The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
Volume of CVEs assigned to CWE-642 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29146HIGH Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 thr | Apr 9, 2026 | 7.5 | 35 | NO | NO |
CVE-2023-0575CRITICAL External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (Devops | Feb 9, 2023 | 9.8 | 27 | NO | NO |
CVE-2018-15382HIGH A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing k | Oct 5, 2018 | 8.6 | 26 | NO | NO |
CVE-2020-27872HIGH This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to e | Feb 4, 2021 | 8.8 | 25 | NO | NO |
CVE-2025-49090HIGH The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution. | Oct 2, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-8754HIGH An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error | Sep 12, 2024 | 8.1 | 23 | NO | NO |
CVE-2022-22154MEDIUM In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attack | Jan 19, 2022 | 6.8 | 23 | NO | NO |
CVE-2025-54566MEDIUM hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327. | Jul 25, 2025 | 5.4 | 21 | NO | NO |
CVE-2020-26186MEDIUM Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerab | Jan 8, 2021 | 6.8 | 21 | NO | NO |
CVE-2019-9496HIGH An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP | Apr 17, 2019 | 7.5 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.